Amgen Technology Private Limited

Encryption Agility Engineer

Amgen Technology Private Limited
Hyderabad
Not disclosed
Work from OfficeWork from Office
Full TimeFull Time
Min. 6 yearsMin. 6 years

Job Description

Encryption Agility Engineer

Career Category

Information Systems

Job Description

Role Name: Specialist Information Security - Encryption Agility Engineer

Job Posting Title: Specialist Information Security - Encryption Agility Engineer

Workday Job Title: Specialist Information Security

Department Name: Trusted Core Technologies

Role Global Career Framework (GCF): 5A

ABOUT AMGEN

Amgen harnesses the best of biology and technology to fight the world's toughest diseases, and make people's lives easier, fuller and longer. We discover, develop, manufacture and deliver innovative medicines to help millions of patients. Amgen helped establish the biotechnology industry more than 40 years ago and remains on the cutting-edge of innovation, using technology and human genetic data to push beyond what's known today.

ABOUT THE ROLE

Role Description:

The Specialist Information Security - Encryption Agility Engineer will serve as a senior hands-on engineer for Amgen's enterprise Encryption Agility Service for Post-Quantum Cryptography (PQC) Readiness Preparation. This role supports the Senior Manager Information Security - Encryption Agility Service Lead and the Senior Specialist Information Security - Encryption Agility Team Architect by executing the technical work needed to build and operate Amgen's enterprise cryptographic inventory, discovery workflows, Cryptographic Bill of Materials (CBOM), remediation tracking, and engineering guidance for encryption, cryptography, crypto agility, and post-quantum readiness. The role is expected to be practical, technical, and service-oriented, with the ability to analyze cryptographic findings across applications, cloud, infrastructure, identity, Public Key Infrastructure (PKI), certificates, Key Management Services (KMS), secrets, data protection, Software as a Service (SaaS), and third-party ecosystems.

This position will translate architecture direction into working implementation tasks, data quality rules, dashboards, tool integrations, remediation tickets, secure patterns, developer guidance, and repeatable Standard Operating Procedures (SOPs). The engineer will partner with Digital Identity Access Service (DIAS), PKI and certificate service owners, Application Security, Artificial Intelligence (AI) Security, Enterprise Architecture, cloud, infrastructure, platform, Risk and Compliance, Procurement, Legal, Third Party Risk Management (TPRM), Operational Technology (OT), and vendor teams to help make Amgen's PQC roadmap measurable, actionable, and sustainable.

Roles & Responsibilities:

  • Execute assigned Encryption Agility Service workstreams, including intake analysis, backlog execution, roadmap tracking, service metrics, reporting inputs, SOP updates, and service improvement actions under the direction of the Senior Manager and Principal Architect.
  • Operate enterprise cryptographic discovery across source code, binaries, cloud key services, endpoints, file systems, network traffic, PKI and certificates, KMS and secrets, vendor attestations, Software Bill of Materials (SBOM) inputs, and Subject Matter Expert (SME) interviews.
  • Build, maintain, and improve the Amgen CBOM using CycloneDX 1.6+ as the target format, including required fields, source systems, ownership attributes, quantum-vulnerability status, remediation status, data quality checks, reporting views, and asset correlation.
  • Support tool integration and data normalization across Amgen Enterprise and cryptographic discovery platforms.
  • Analyze cryptographic scan outputs, source code findings, certificate chains, cipher suite configurations, Transport Layer Security (TLS) settings, Secure Shell (SSH) settings, Open Authorization (OAuth), Security Assertion Markup Language (SAML), JSON Web Token (JWT) patterns, cloud key configurations, and key or secret storage patterns.
  • Implement and document remediation patterns approved by the Principal Architect, including hybrid TLS, proxy-based crypto agility, Network encapsulation, Internet Protocol Security (IPsec), Media Access Control Security (MACsec), Key Management Interoperability Protocol (KMIP), Public-Key Cryptography Standard #11 (PKCS#11), provider libraries, custom code libraries, symmetric cryptography, Hash-Based Message Authentication Code (HMAC), TLS termination, reverse proxies, encrypted overlays, segmentation controls, compensating controls, and risk-based replacement or decommission pathways.
  • Coordinate with DIAS, PKI service owners, certificate management teams, identity teams, cloud, infrastructure, and platform teams on certificate visibility, Certificate Lifecycle Manager (CLM) evaluation, certificate rotation, manual-to-automated deployment migration, post-quantum PKI readiness, hybrid certificate testing, Certificate Authority (CA) modernization, KMS strategy, Hardware Security Module (HSM) patterns, secrets management, key rotation, key retirement, storage standards, ownership, reporting, and centralized or federated control options.
  • Partner with Application Security, AI Security, Enterprise Architecture, Development and Operations (DevOps), and engineering teams to publish approved cryptographic libraries, secure code examples, reusable patterns, Continuous Integration/Continuous Delivery (CI/CD) controls, Secure Software Development Life Cycle (SSDLC) requirements, scanning rules, developer remediation playbooks, and practical implementation guidance.
  • Apply Amgen's approved quantum risk-prioritization approach to discovery and remediation planning for business-critical applications, high-volume sensitive data flows, third-party dependencies, identity services, legacy platforms, Key Computerized Systems (KCS), validated Good x Practice (GxP) systems, and OT scope.
  • Support vendor and third-party technical governance with Procurement, Legal, Risk and Compliance, TPRM, and business owners by preparing technical questionnaire content, CBOM requests, evidence reviews, roadmap tracking, contract language inputs, escalation triggers, and supplier remediation follow-up.
  • Provide technical escalation and mentoring for Global Career Framework level 4 (L4) analysts and contributors, maintain cryptographic knowledge articles and implementation guides, and track changes in National Institute of Standards and Technology (NIST), Internet Engineering Task Force (IETF), National Security Agency Commercial National Security Algorithm Suite 2.0 (NSA CNSA 2.0), International Organization for Standardization (ISO), Health Insurance Portability and Accountability Act (HIPAA), Health Information Trust Alliance (HITRUST), and broader industry cryptography guidance.

Basic Qualifications and Experience:

  • Doctorate degree in Information Security, Cybersecurity, Cryptography, Security Architecture, Computer Science, Information Technology, Engineering, or related field OR
  • Master's degree with 4 to 6 years of experience in Information Security, Cybersecurity, Cryptography, Security Architecture, Computer Science, Information Technology, Engineering, or related field OR
  • Bachelor's degree with 6 to 8 years of experience in Information Security, Cybersecurity, Cryptography, Security Architecture, Computer Science, Information Technology, Engineering, or related field OR
  • Diploma with 10 to 12 years of experience in Information Security, Cybersecurity, Cryptography, Security Architecture, Computer Science, Information Technology, Engineering, or related field

Functional Skills:

Must-Have Skills:

  • Strong hands-on knowledge of enterprise cryptography, including PKI, X.509 certificates, TLS, cipher suites, KMS, HSMs, secrets management, key lifecycle, encryption at rest, encryption in transit, cloud key services, identity protocols, and certificate lifecycle automation.
  • Practical experience with cryptographic discovery, CBOM-driven inventory, source code scanning, network and endpoint telemetry, cloud key service analysis, false-positive triage, data quality controls, dashboards, and remediation tracking.
  • Working knowledge of post-quantum cryptography, crypto agility, NIST-approved algorithms and standards, hybrid transition patterns, Steal-Now-Decrypt-Later (SNDL) risk reduction, and risk-prioritized remediation.
  • Ability to convert cryptographic policy, architecture direction, and scan findings into actionable engineering guidance across CI/CD, SSDLC, cloud platforms, PKI and certificates, KMS and secrets, identity, infrastructure, applications, third-party governance, and risk management.

Good-to-Have Skills:

  • Hands-on experience with ServiceNow CMDB/GRC, Guard, Wiz, Qualys, Fortinet, Netskope, CrowdStrike, GitLab, Veracode, GitGuardian, Amazon Web Services (AWS) KMS, AWS Certificate Manager, AWS Secrets Manager, Microsoft PKI, Sectigo, HashiCorp Vault, HSMs, CLM platforms, and SIEM/data lake integrations.
  • Experience creating or operating CBOM/SBOM data models using CycloneDX 1.6+, Application Programming Interfaces (APIs), Comma-Separated Values (CSV), JavaScript Object Notation (JSON), dashboards, data quality checks, and audit-ready reporting.
  • Experience with PKI modernization, certificate automation, certificate rotation, CA hierarchy changes, hybrid certificate testing, and Post-Quantum Public Key Infrastructure (PQ-PKI) transition support.
  • Experience with key management and secrets management across AWS, Azure, on-premises platforms, HSMs, vault technologies, automation workflows, and centralized or federated operating models.
  • Experience with application security, DevOps, SSDLC governance, CI/CD quality gates, approved cryptographic libraries, static analysis, dynamic analysis, composition analysis, and developer enablement.
  • Experience in pharmaceutical, life sciences, regulated, validated, GxP, KCS, manufacturing, OT, or other change-controlled environments.
  • Scripting and automation experience with Python, PowerShell, Bash, Representational State Transfer Application Programming Interfaces (REST APIs), data pipelines, parsing of certificate or scan data, or lightweight integration development.

Professional Certifications:

  • Certified Information Systems Security Professional (CISSP) (preferred)
  • Certified Cloud Security Professional (CCSP), AWS Certified Security - Specialty, Microsoft Azure Security Engineer, or equivalent cloud security certification (preferred)
  • Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), or Certified in Risk and Information Systems Control (CRISC) (preferred)
  • Security+, Systems Security Certified Practitioner (SSCP), or equivalent security certification (preferred)
  • Relevant PKI, KMS, HSM, cryptographic discovery, certificate lifecycle management, cloud key management, or post-quantum cryptography training/certification (preferred)

Soft Skills:

  • Excellent analytical, troubleshooting, and problem-solving skills.
  • Strong technical ownership and ability to drive complex discovery, analysis, and remediation work to completion.
  • Strong verbal and written communication skills for technical, business, compliance, procurement, and vendor audiences.
  • Ability to translate cryptographic findings into clear risk statements, remediation options, and implementation steps.
  • Ability to influence without direct authority across global security, Digital, Technology and Innovation (DTI), DIAS, procurement, legal, compliance, OT, infrastructure, cloud, and application teams.
  • High degree of initiative, accountability, judgment, and self-motivation in ambiguous or evolving technical domains.
  • Team oriented, with a focus on shared outcomes, reusable patterns, practical implementation, and service maturity.
  • Strong coaching and mentoring skills for L4 analysts and technical contributors.
  • Strong documentation, presentation, and knowledge-sharing skills for technical reviews, service updates, and architecture forums.

EQUAL OPPORTUNITY STATEMENT

Amgen is an Equal Opportunity employer and will consider you without regard to your race, color, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, or disability status.

We will ensure that individuals with disabilities are provided with reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please contact us to request an accommodation.

.

Experience Level

Senior Level

Job role

Work location
Work locationIndia - Hyderabad
Department
DepartmentIT & Information Security
Role / Category
Role / CategoryIT Security
Employment type
Employment typeFull Time
Shift
ShiftDay Shift

Job requirements

Experience
ExperienceMin. 6 years

About company

Name
NameAmgen Technology Private Limited
Job posted by Amgen Technology Private Limited

Similar jobs you can apply for

Manufacturing / Production
V5 Global

Installation Engineer

V5 Global
Hyderabad
₹17,000 - ₹24,500*
Work from Office
Full Time
Any experience
Basic English
Protech Progressive Technology

Testing Engineer

Protech Progressive Technology
Dhulapally, Hyderabad
₹12,000 - ₹13,000
Work from Office
Full Time
Any experience
Basic English
Sushwa It Services

Computer Hardware Technician

Sushwa It Services
Moosapet, Hyderabad
₹10,000 - ₹12,500
Work from Office
Full Time
Any experience
Basic English
Sushwa It Services

Hardware & Network Engineer

Sushwa It Services
Moosapet, Hyderabad
₹10,000 - ₹15,000
Work from Office
Full Time
Any experience
Basic English
Infonet Online Solutions Private Limited

Fiber Field Engineer

Infonet Online Solutions Private Limited
Ram Nagar, Hyderabad
₹25,000 - ₹26,000
Field Job
Full Time
Min. 1 year
No English Required
VI Global Fibertel Private Limited

Fiber Technician & Helper

VI Global Fibertel Private Limited
Medchal, Hyderabad
₹15,000 - ₹18,000
Field Job
Full Time
Any experience
No English Required

You can expect a minimum salary of 0 INR. The salary offered will depend on your skills, experience and performance in the interview.

The candidate should have completed the required education and people who have 6 to 8 years are eligible to apply for this job. You can apply for more jobs in Hyderabad to get hired quickly.

The candidate should have sound communication skills and sound communication skills for this job.

Both Male and Female candidates can apply for this job.

No, it's not a work from home job and can't be done online. You can explore and apply for other work from home jobs in Hyderabad at apna.

No work-related deposit needs to be made during your employment with the company.

Go to the apna app and apply for this job. Click on the apply button and call HR directly to schedule your interview.

The last date to apply for this job is . For more details, download apna app and find Full Time jobs in Hyderabad . Through apna, you can find jobs in 64 cities across India. Join NOW!